❌

Reading view

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)

Posted by Joe via Fulldisclosure on Sep 22

HP Advance / HP Output Central
Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file
write/delete
CVE-2026-89082, CVE-2026-89083, CVE-2026-89084

================================================================
SUMMARY
================================================================

Vendor: HP Inc.
Product family named by HP: HP Advance
Products in HP's update table: HP AC Print & Scan; HP Output Central
Components:...
  •  

CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)

Posted by Raschin Tavakoli via Fulldisclosure on Sep 22

nullFaktor Security Advisory < 2026-09-10 >
===========================================================
Title: Pre-Authentication Remote Code Execution in SAP
Extended Passport (EPP) processing library
Affected Components: ICM, SAP Web Dispatcher, dialog work processes

Vulnerability: Stack based Buffer Overflow
CVE: CVE-2026-44756

Impact: Critical
CVSS 4.0 Vector:...
  •  

[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
TigerGraph Community Edition 4.2.4.

Type: Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (CWE-798)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: command execution as the tigergraph service user (uid 1001), which owns the engine, graph data, catalog and
configuration tree
Authentication: unauthenticated (shipped default credentials)...
  •  

[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Teltonika RutOS 00.07.06.21.

Type: Authenticated ipsec.lua logread command injection with reflected output (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the router, with command output reflected into the JSON response
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...
  •  

APPLE-SA-09-14-2026-10 Xcode 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-10 Xcode 27

Xcode 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149040.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Xcode IDE
Available for: macOS Tahoe 26.6 and later
Impact: An app may be able to access user-sensitive data
Description: A permissions issue...
  •  

APPLE-SA-09-14-2026-9 Safari 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-9 Safari 27

Safari 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149039.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Safari
Available for: macOS Sequoia and macOS Tahoe
Impact: A malicious website may be able to determine what apps a user
has installed...
  •  

APPLE-SA-09-14-2026-8 visionOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-8 visionOS 27

visionOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149038.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Vision Pro (all models)
Impact: Processing a maliciously crafted image may lead to unexpected...
  •  

APPLE-SA-09-14-2026-7 watchOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-7 watchOS 27

watchOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149037.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple Watch Series 9 and later
Impact: Processing a maliciously crafted image may lead to unexpected...
  •  

APPLE-SA-09-14-2026-6 tvOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-6 tvOS 27

tvOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149036.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: Apple TV 4K 2nd generation and later
Impact: Processing a maliciously crafted image may lead to unexpected...
  •  

APPLE-SA-09-14-2026-5 macOS Sequoia 15.8

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-5 macOS Sequoia 15.8

macOS Sequoia 15.8 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149043.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: macOS Sequoia
Impact: Processing a maliciously crafted image may lead to unexpected...
  •  

APPLE-SA-09-14-2026-4 macOS Tahoe 26.7

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-4 macOS Tahoe 26.7

macOS Tahoe 26.7 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149042.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image may lead to unexpected
process...
  •  

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

macOS Golden Gate 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149035.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro...
  •  

Code Security Review tool

Posted by E. Kellinis on Sep 22

Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro
is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple
languages. It's backed by an ML classifier trained on real patches to catch subtle issues. Beyond scanning, it offers
interactive call graphs and data-flow diagrams, a bug tracker, a private research wiki,...
  •  

CFP No cON Name 2k26 - Palma, Mallorca - Spain

Posted by Jose Nicolas Castellano on Sep 22

No cON Name 2026 - Palma, Mallorca - Balearic Islands

************************************
*****Β  Call For PapersΒ  Β  Β  Β  ******
************************************

https://www.noconname.org/call-for-papers/

Exact place not disclosed until a few weeks before due celebration.

Β  Β  * INTRODUCTIONfulldisclosure () seclists org
The organization hasΒ  opened CFP proposals. No cON Name is the eldest
Hacking
and Security Conference in Span....
  •  

CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)

Posted by Louis Sanchez via Fulldisclosure on Sep 22

Posting this as an update rather than a first disclosure. The advisory
went public on 2026-08-04 with no vendor fix. Penpot has shipped two
releases since then, 2.17.1 and 2.17.2 -- the latter 14 days ago, on
2026-08-27 -- and I re-checked the code this morning: the missing
permission check is still missing in both, and in every release before
them. It was fixed on develop the day after this advisory went public.
That fix has never shipped....
  •  

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

iOS 27 and iPadOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149034.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch...
  •  

[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Opengear NGCS 25.11.8.

Type: Authenticated PDU name command injection to root via io.popen (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the out-of-band console manager
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...
  •  

[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
LCDS Laquis SCADA.

Type: Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (CWE-434)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary native code execution inside the SCADA web and HMI process, which also hosts the Modbus TCP listener
Authentication: unauthenticated (no password configured is the default)

Full technical analysis and a...
  •  

[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Ecava IntegraXor IGX 16.0.701.10.

Type: Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as Administrator on a Web SCADA HMI host
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...
  •  

[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Devolutions Server (DVLS) 2026.2.14.0.

Type: PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (CWE-862)
CVSS: 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Impact: arbitrary PowerShell execution as NT AUTHORITY\SYSTEM on the Devolutions Server host
Authentication: authenticated administrator (no PAM licence, no PAM role)

Full technical analysis and a...
  •  
❌